Avira, PWI and a probable False Positive

Chillum - Dreamweaver
Chillum - Dreamweaver Posts: 887 Arc User
edited July 2010 in Support Desk
Hello.

Updated my Avira anti virus software before a system scan last night and it came up with a few things:

[Coped from the log]

E:\PWi\v166_XP\PWI_v166_XP.part2.rar
[0] Archive type: RAR
--> install.exe
[1] Archive type: RSRC
--> Object
[DETECTION] Is the TR/Obfuscated.JB.134 Trojan
E:\PWi\v166_XP\PWI Installation Files\install.exe
[0] Archive type: RSRC
--> Object
[DETECTION] Is the TR/Obfuscated.JB.134 Trojan
E:\v166_XP\PWI_v166_XP.part2.rar
[0] Archive type: RAR
--> install.exe
[1] Archive type: RSRC
--> Object
[DETECTION] Is the TR/Obfuscated.JB.134 Trojan
E:\v166_XP\PWI Installation Files\install.exe
[0] Archive type: RSRC
--> Object
[DETECTION] Is the TR/Obfuscated.JB.134 Trojan
Begin scan in 'F:\' <Games>
F:\Perfect World International\uninstall.exe
[DETECTION] Is the TR/Obfuscated.JB.134 Trojan

I imagine this is a false positive as Avira has had previous with regards to that and PWI for me.

Just putting this out there for other people or PWI to let others know or confirm that it is a false positive.

Regards.

Edit: Have sent in a potential false positive report to Avira.
[SIGPIC][/SIGPIC]
Post edited by Chillum - Dreamweaver on

Comments

  • Chillum - Dreamweaver
    Chillum - Dreamweaver Posts: 887 Arc User
    edited July 2010
    Update from Avira:

    A listing of files alongside their results can be found below:
    File ID Filename Size (Byte) Result
    25816512 install.exe 1.14 MB FALSE POSITIVE


    Please find a detailed report concerning each individual sample below:
    Filename Result
    install.exe FALSE POSITIVE

    The file 'install.exe' has been determined to be 'FALSE POSITIVE'. In particular this means that this file is not malicious but a false alarm. Detection will be removed from our virus definition file (VDF) with one of the next updates.


    Haven't sent anything about the uninstall.exe as I think I might have accidentally deleted it.

    b:surrender

    Regards.
    [SIGPIC][/SIGPIC]